Kelp DAO Drained: 92M Bridge Hack Exposes Critical DeFi Infrastructure Flaw
In what has become the most controversial blockchain security incident of April 2026, the Kelp DAO LayerZero bridge was exploited for $292 million in rsETH tokens. The attack didn’t target a smart contract bug—it deceived the entire cross-chain verification system through a sophisticated infrastructure compromise that has sent shockwaves through the DeFi ecosystem.
The Attack: How $292M Was Stolen Without a Code Exploit
On April 19, 2026, attackers executed a novel attack vector that bypassed traditional smart contract security entirely. Instead of finding a vulnerability in the bridge’s code, they compromised the off-chain infrastructure that verifies cross-chain transactions:
- Poisoned RPC Nodes: Attackers gained control of internal RPC (Remote Procedure Call) nodes used by Kelp DAO’s verification system.
- DDoS on External Nodes: Simultaneous distributed denial-of-service attacks knocked out external backup nodes, leaving the system reliant on the compromised internal nodes.
- False Data Injection: The poisoned nodes fed false transaction data to the bridge, reporting that tokens had been “burned” on the source chain when no such burn occurred.
- Phantom Mint: Based on this fraudulent data, the Ethereum bridge contract minted and released rsETH tokens that were never backed by actual locked assets.
The entire attack hinged on a single point of failure: the verification network’s reliance on a limited set of nodes that could be selectively compromised and isolated.
Who Is Behind the Attack?
Blockchain forensics firms have preliminarily linked the attack to North Korea’s Lazarus Group, a state-sponsored hacking collective responsible for some of the largest crypto heists in history, including the $625M Axie Infinity Ronin bridge exploit in 2022. The sophistication of the infrastructure attack—combining node compromise, DDoS, and cross-chain message manipulation—matches Lazarus’s known operational patterns.
Systemic Impact: $17 Billion in Withdrawals
The Kelp DAO exploit triggered a broader liquidity crisis across DeFi. In the aftermath, an estimated $17 billion was withdrawn from major lending protocols like Aave as users rushed to de-risk positions. The panic was fueled by concerns that other bridges using similar verification mechanisms could be vulnerable to the same attack pattern.
Why This Matters
- Infrastructure > Code: This hack proves that even audited, bug-free smart contracts can be compromised if the off-chain infrastructure they rely on is weakened.
- Cross-Chain Risk: Bridges remain the weakest link in DeFi, holding large pools of locked assets and relying on complex messaging systems that are difficult to secure end-to-end.
- Centralization Vulnerability: The attack exploited a centralized verification layer—a reminder that “decentralized” protocols often have critical centralized dependencies.
- State-Sponsored Threat: Lazarus Group’s involvement underscores that DeFi protocols are now targets of nation-state-level actors with significant resources and patience.
Philippines Regulatory Update: SEC Warns Against Unregistered Platforms
In related blockchain security news, the Philippines Securities and Exchange Commission (SEC) issued advisories in April 2026 against eight unregistered cryptocurrency trading platforms operating in the country: Vest, Ostium, Deriv, Pacifica, Aevo, Orderly Network, dYdX, and gTrade. The SEC warned that these platforms were soliciting investments without required licenses, and that promoting them could result in criminal liability including fines and imprisonment.
This regulatory action is part of ongoing efforts to protect Filipino investors and bring clarity to the country’s crypto landscape. Users are advised to verify that any platform they use is registered with the SEC before depositing funds.
What Comes Next for Bridge Security
The Kelp DAO exploit will likely accelerate several trends in DeFi security:
- Decentralized Verification: Bridges will move toward more decentralized oracle networks with redundancy that makes selective compromise impossible.
- Real-Time Monitoring: Protocols will implement automated anomaly detection to flag unusual cross-chain message patterns.
- Insurance Requirements: Users and institutional participants will demand proof of insurance coverage before bridging significant assets.
- Regulatory Scrutiny: Expect increased regulatory attention on bridge operators, potentially classifying them as money transmitters or custodians.
For now, the message is clear: cross-chain bridges remain high-value targets, and the attack surface extends far beyond smart contract code. Infrastructure security is now DeFi security.